We Built Private Post-Training and Inference for Frontier Models
First multi-GPU TEE stack for training trillion-parameter models with under 10% overhead.
Security projects from Show HN — penetration testing, encryption, privacy tools, and vulnerability scanners.
First multi-GPU TEE stack for training trillion-parameter models with under 10% overhead.
First real supply-chain defense for AI agent ecosystems; catches nation-state-grade payloads.
100% deterministic SYSTEM escalation from Chrome sandbox via audited syscall.
Proves text safety ≠ tool-call safety; catches hidden harmful executions deterministically.
Identifies LLM models by password bias patterns when they refuse to tell you.
Responds to every internet knock with a tailored poem. Pure whimsy meets security observation.
Empirical proof: AI agents ignore stop commands and delete emails without enforceable boundaries.
E2E voice over Tor in pure Bash; no server, no accounts, .onion address is your identity.
A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.
Agents never see credentials — brokered access beats retrieval for prompt injection safety.
Wire-protocol parsing gates agent actions before they hit production—no LLM gateway does this.
Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally
Cable proximity alerts on shadow fleet vessels when MarineTraffic only shows positions.
Turns any Linux laptop into a curl-able IoT pentest lab with per-query DNS logging.
eBPF runtime visibility for AI agents—first tool solving the trust problem with Claude Code and similar.
eBPF kernel drops + dual ML engine beats Cloudflare in latency, single microsecond blocks.
Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, or in the cloud.
Endpoint telemetry for AI agents when cloud logs miss local activity.
Blocks unauthorized agent actions before execution with cryptographic intent binding.
Searchable encryption running queries over ciphertext faster than AWS KMS direct.
macOS Endpoint Security frameworks beat sandbox-exec for AI agent isolation.
CSS flex ordering makes textContent return garbage while visual rendering stays perfect.
Per-request push approval for agents with sub-ms rule matching; beats static policies cold.
First open standard for agent identity—solves a real security gap Cisco documented.
A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.
Metasploit for CI/CD pipelines with terminal UI and cloud provider pivoting.
Homomorphic encryption on vector search when Pinecone and Qdrant require plaintext on server.
O-cap security model beats the credential-bag approach every agent framework currently uses.
Motor-control maze analysis targets LLMs where Turnstile and hCaptcha fail.
Agent auth via key-signing beats API keys and OAuth for autonomous systems.
The Runtime Security Layer for OpenClaw/Hermes-agent, the essential safety harness for PII & sensitive credentials protection.
Moves credential security from prompt-injection hope to OS process isolation for agents.
Detects sycophancy and jailbreak drift in LLMs without needing model weights.
Finally, a certificate manager that works for home labs, not just enterprises.
Post-trained model for offensive security instead of wrapping GPT with safety refusals.
AI agents get credentials without ever seeing them—SQL prepared statements for secrets.
Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
Fills the EDR blind spot for AI tooling — timely and actually useful today.
eBPF sock_ops injection beats GoodbyeDPI with kernel-level packet manipulation.
Cross-correlates threat intel across four lenses where incumbents stay siloed.
an implementation of the ideas in Erik Meijer's "Guardians of the Agents: Formal Verification of AI Workflows" (Communications of the ACM, January 2026)
Applies formal verification to prevent prompt injection before any tool executes.
Kernel-enforced agent sandboxing that blocks .env access without container overhead.
Solves agent identity before standards bodies even finish the spec.
RFC 8693 agent identity with delegation chains before standards even exist.
A privacy-preserving Raspberry Pi home security camera that uses advanced end-to-end encryption.
Reproducible builds across entire stack with E2E encryption, unlike Ring or Nest.
Scoped runtime credentials for AI agents replace insecure .env API keys.
Post-quantum hybrid encryption finally arrives in PHP where it's been missing.
Hardware-enforced TEEs mean even the host OS can't read your AI prompts.
Hardware-bound SSH keys sealed in TPM without messy PKCS11 config.
Hardware-enforced attestation beats the usual 'trust us' promises of cloud guardrails.
Live PGP round-trip test with streaming logs beats static key checkers.
Browser-native encrypted files, no app needed, works offline permanently.
Intent contracts catch what agents were supposed to do, not just what they did.
Security scanner for Agent Skills — uncover hidden threats before deployment.
Docker sandbox execution catches runtime threats static analysis alone misses.
1044 projects